CVE-2026-70594 - CERT CVE
ID CVE-2026-70594
Sažetak Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted. This issue is fixed in version 6.54.1.
Reference
CVSS
Base: 6.7
Impact: 5.5
Exploitability:1.2
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH LOW
CVSS vektor CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
Zadnje važnije ažuriranje 05-08-2026 - 15:17
Objavljeno 04-08-2026 - 22:17